Live data from Hacker News

Google Chrome Hacked?

vupen.com

51–60 of 223 posts

Re: Google Chrome Hacked?

#51
post #34

Earlier quoted context omitted.

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

"They can either pay a nominal fee for doing their security work for them, or they can hire some equally talented people and fund this type of research on their own internally." What makes you think they don't already? You make it sound like Google doesn't give a shit about security. That clearly isn't the case.

Google employs several of the best well-known security researchers in the world, and no doubt many more that we haven't heard much about.

That doesn't mean they're going to find everything, though.

At the end of the day, private companies are perfectly within their rights to do offensive research against Google products, to be selective about how they disclose their results, and to tell the public whatever they want about those results. As long as they aren't lying, there's nothing unethical about it.

Re: Google Chrome Hacked?

#52
post #44
post #31

Earlier quoted context omitted.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

Out of speculation, would this tie in at all to an article I saw on HN a while back about the Government hiring 3rd parties to hack Google for some reason?

Is it wrong for our government to do any security research? I mean can good things not come out of it? Be thankful it was reported.

Re: Google Chrome Hacked?

#53
post #18
post #7

Earlier quoted context omitted.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

"With 20 to 25 binary analysis and private exploits/PoCs released each month, the VUPEN In-Depth Binary Analysis and Exploits service allows organizations and corporations to evaluate and qualify risks, and protect national infrastructures and corporate assets from emerging attacks." If you are interested in protecting your network, patches and workarounds are your first priority, not "proof of concept" exploits.

Do you do a lot of in-the-field security work? How do you work around a vulnerability without being able to see whether and how it works?

Re: Google Chrome Hacked?

#54

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

No disrespect intended, but, it doesn't negatively predispose anyone who conducts or utilizes vulnerability research professionally, so I doubt your concern matters much to them.

Re: Google Chrome Hacked?

#55
post #42

Earlier quoted context omitted.

Who cares if they sound unprofessional to you? Very obviously they produce.

I am still waiting for that obvious evidence. That includes more details and also tests on the latest dev version of Chrome (Chromium). I am not defending Google in any way, but some claim with no real evidence shouldn't convince anybody.

I saw a similar mentality on the Skype for Mac thread, as if there is a huge incentive to just make up vulnerabilities. More or less, when HN threads don't want something to be true ("terrible Chrome vulnerability with no public info and no pending patch!"), they make up controversies to keep them from having to accept that it's true. It's a bad habit.

Re: Google Chrome Hacked?

#56
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

Do policemen work for free? It's a dirty job, I 'd want to be paid

That's a poor example. Policeman get paid to protect everyone; police protection is not (usually) a subscription service.

Re: Google Chrome Hacked?

#57
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

Looking at VUPEN services it sounds like HBGary twin : http://www.vupen.com/english/services/ "offensive security", yep. The guys are dirty like the Gary. Why a racket and government always means a happy marriage?

One difference is that it appears that these VUPEN folks are not entirely incompetent.

Re: Google Chrome Hacked?

#58
post #31
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

On an exploit like this, I expect a patch. I'm sure people at Google and abroad (if the exploit exists in Chromium) are scrambling to find it, both for the e-cred and just to make other people safer.

Re: Google Chrome Hacked?

#59
post #42

Earlier quoted context omitted.

Who cares if they sound unprofessional to you? Very obviously they produce.

I am still waiting for that obvious evidence. That includes more details and also tests on the latest dev version of Chrome (Chromium). I am not defending Google in any way, but some claim with no real evidence shouldn't convince anybody.

Operating under the assumption that this is for some reason made up is an extraordinarily bad idea.

Regardless, how they write is still offtopic.

Re: Google Chrome Hacked?

#60

Earlier quoted context omitted.

like it or not, it's been vernacular for quite some time. how do you feel about pwn2own? the pwnies?

"Whore" is vernacular, but that doesn't mean the FBI uses the word when they announce they've cracked a prostitution ring.

Only hiring offensive security vendors who won't use the term 'pwned' is roughly equivalent to trying to purchase a hand job from someone who won't use the term 'whore'. Neither is likely to get you very far.
Post reply on HN